Loading market data...

Bitkey Patches Vulnerability After Researcher Report, Says No Funds at Risk

Bitkey Patches Vulnerability After Researcher Report, Says No Funds at Risk

Bitkey, a company offering self-custody cryptocurrency storage, has addressed a security vulnerability flagged by an external researcher. The company confirmed that no user funds were ever at risk and that the issue has been resolved.

The vulnerability report

A researcher identified a potential weakness in Bitkey's software and reported it through the company's disclosure program. Bitkey did not name the researcher or provide technical details about the flaw, but acknowledged the report and moved quickly to investigate.

Such reports are common in the crypto security space, where independent researchers routinely scan for bugs. Bitkey said the vulnerability was contained and did not affect the core security of its hardware wallet or the associated mobile app.

Bitkey's response

Bitkey released a patch after verifying the researcher's findings. The company did not say when the patch was deployed, but noted that the fix was applied before any exploitation could occur. Users were not required to take any action, though Bitkey recommended keeping software up to date.

The company also thanked the researcher for the responsible disclosure. Bitkey operates a bug bounty program that rewards researchers for finding and reporting vulnerabilities, though it did not disclose whether a bounty was paid in this case.

No risk to funds

Bitkey stressed that the vulnerability did not put customer funds in danger. The company's hardware wallet is designed to keep private keys offline, and the reported issue did not compromise that isolation. Bitkey said the flaw was in a peripheral component, not in the key management system.

This is not the first time a crypto-related wallet has faced a security report. But Bitkey's quick response and clear assurance that funds were safe helped limit concern among its user base.

Bitkey has not disclosed further details about the vulnerability, citing security best practices. The company continues to encourage users to install the latest updates and to report any suspicious activity. The researcher's identity remains private, and Bitkey has not announced any changes to its bug bounty program.